CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,856)
page 254 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-42428 | Hig | 0.57 | 8.8 | 0.03 | Mar 29, 2023 | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results… | ||
| CVE-2022-42426 | Hig | 0.57 | 8.8 | 0.03 | Mar 29, 2023 | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results… | ||
| CVE-2023-25350 | Hig | 0.57 | 8.8 | 0.01 | Mar 24, 2023 | Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity of the user's input data. The parameters passed from the front end to the back end are controllable, which will lead to SQL injection. | ||
| CVE-2023-28663 | Hig | 0.57 | 8.8 | 0.01 | Mar 22, 2023 | The Formidable PRO2PDF WordPress Plugin, version < 3.11, is affected by an authenticated SQL injection vulnerability in the ‘fieldmap’ parameter in the fpropdf_export_file action. | ||
| CVE-2023-28661 | Hig | 0.57 | 8.8 | 0.01 | Mar 22, 2023 | The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in the 'value' parameter in the get_popup_data action. | ||
| CVE-2023-28660 | Hig | 0.57 | 8.8 | 0.01 | Mar 22, 2023 | The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list action. | ||
| CVE-2023-28659 | Hig | 0.57 | 8.8 | 0.01 | Mar 22, 2023 | The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_save_downs action. | ||
| CVE-2023-1471 | Hig | 0.57 | 8.8 | 0.01 | Mar 17, 2023 | The WP Popup Banners plugin for WordPress is vulnerable to SQL Injection via the 'banner_id' parameter in versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | ||
| CVE-2023-27037 | Hig | 0.57 | 8.8 | 0.01 | Mar 16, 2023 | Qibosoft QiboCMS v7 was discovered to contain a remote code execution (RCE) vulnerability via the Get_Title function at label_set_rs.php | ||
| CVE-2023-24732 | Hig | 0.57 | 8.8 | 0.01 | Mar 15, 2023 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update function. | ||
| CVE-2023-24731 | Hig | 0.57 | 8.8 | 0.01 | Mar 15, 2023 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function. | ||
| CVE-2023-24730 | Hig | 0.57 | 8.8 | 0.01 | Mar 15, 2023 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function. | ||
| CVE-2023-24729 | Hig | 0.57 | 8.8 | 0.01 | Mar 15, 2023 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function. | ||
| CVE-2023-24728 | Hig | 0.57 | 8.8 | 0.01 | Mar 15, 2023 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function. | ||
| CVE-2023-25206 | Hig | 0.57 | 8.8 | 0.01 | Mar 14, 2023 | PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection. | ||
| CVE-2023-27463 | Hig | 0.57 | 8.8 | 0.01 | Mar 14, 2023 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The audit log form of affected applications is vulnerable to SQL injection. This could allow authenticated remote attackers to execute arbitrary SQL queries on the server database. | ||
| CVE-2023-24763 | Hig | 0.57 | 8.8 | 0.01 | Mar 6, 2023 | In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0. | ||
| CVE-2023-24789 | Hig | 0.57 | 8.8 | 0.01 | Mar 6, 2023 | jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report component. | ||
| CVE-2023-0953 | Hig | 0.57 | 8.8 | 0.01 | Mar 1, 2023 | Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources. | ||
| CVE-2023-24656 | Hig | 0.57 | 8.8 | 0.01 | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subject parameter under the Create Ticket function. |
- risk 0.57cvss 8.8epss 0.03
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results…
- risk 0.57cvss 8.8epss 0.03
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results…
- risk 0.57cvss 8.8epss 0.01
Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity of the user's input data. The parameters passed from the front end to the back end are controllable, which will lead to SQL injection.
- risk 0.57cvss 8.8epss 0.01
The Formidable PRO2PDF WordPress Plugin, version < 3.11, is affected by an authenticated SQL injection vulnerability in the ‘fieldmap’ parameter in the fpropdf_export_file action.
- risk 0.57cvss 8.8epss 0.01
The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in the 'value' parameter in the get_popup_data action.
- risk 0.57cvss 8.8epss 0.01
The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list action.
- risk 0.57cvss 8.8epss 0.01
The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_save_downs action.
- risk 0.57cvss 8.8epss 0.01
The WP Popup Banners plugin for WordPress is vulnerable to SQL Injection via the 'banner_id' parameter in versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
- risk 0.57cvss 8.8epss 0.01
Qibosoft QiboCMS v7 was discovered to contain a remote code execution (RCE) vulnerability via the Get_Title function at label_set_rs.php
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update function.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function.
- risk 0.57cvss 8.8epss 0.01
PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.
- risk 0.57cvss 8.8epss 0.01
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The audit log form of affected applications is vulnerable to SQL injection. This could allow authenticated remote attackers to execute arbitrary SQL queries on the server database.
- risk 0.57cvss 8.8epss 0.01
In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0.
- risk 0.57cvss 8.8epss 0.01
jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report component.
- risk 0.57cvss 8.8epss 0.01
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subject parameter under the Create Ticket function.